At Lumiture, we're building next-generation solutions that fuse AI, data, and modern engineering to power intelligent experiences across industries. We're not just coding apps - we're shaping how technology helps businesses think, learn, and evolve.
If you love solving big problems, experimenting with cutting-edge tools, and making an impact from day one, you'll feel right at home here.
The Role:
A unique opportunity to grow alongside a rapidly evolving team, supporting a government agency where we can make a meaningful impact.
We're looking for a Multi-Cloud Security & Compliance Engineer to play a pivotal role in securing Oracle Cloud Infrastructure (OCI) and Google Cloud Platform (GCP) environments supporting the Department of Veterans Affairs (VA). You'll establish and enforce a unified security posture across both clouds, oversee permissions boundaries with Zero Trust in mind, and ensure every deployment meets stringent federal requirements, including FedRAMP High, FISMA, and NIST 800-53.
In this role, you will lead technical direction across multiple cloud workstreams, translating regulatory frameworks into automated guardrails and building the centralized monitoring that keeps a mission-critical environment secure. You'll collaborate with security, governance, and audit teams to validate compliance throughout the delivery lifecycle.
What You’ll Have Opportunities to Do:
- Establish and enforce an integrated security posture spanning GCP and OCI environments
- Define security guardrails, standard configurations, and baseline security controls to ensure consistency across all cloud workstreams
- Manage identity federation between cloud environments and implement least-privilege IAM policies, role structures, and segregation of duties across distinct cloud hierarchies
- Configure and operate centralized security monitoring (GCP Security Command Center, OCI Cloud Guard) to unify threat detection, vulnerability visibility, and compliance tracking
- Integrate logs, alerts, and telemetry into enterprise monitoring systems and orchestrate incident response playbooks
- Translate regulatory frameworks such as CIS Benchmarks, HIPAA, FISMA, and NIST 800-53 into automated cloud security guardrails
- Identify vulnerabilities, policy deviations, and architectural risks, then recommend and implement remediation to continuously improve security posture
- Partner with security, governance, and audit teams to ensure all deployments meet VA compliance requirements and program-specific directives
What We’re Looking For:
- US Citizens or Dual Citizens (due to clearance requirements)
- Bachelor's degree in computer science, engineering, information systems, or a related technical discipline (10 years of additional work experience may be considered in lieu of a degree)
- 5 to 10 years of experience in cloud security engineering, enterprise security architecture, or compliance programs
- Minimum of 3 years leading technical teams, including developing technical standards for cloud and on-prem environments and providing technical direction to ensure compliance
- Deep knowledge of GCP and OCI security services, IAM models, encryption, network security, and monitoring architecture
- Hands‑on experience configuring cloud security tools such as:
- Security Command Center and OCI Cloud Guard
- IAM federation and external identity provider integration
- Logging pipelines and vulnerability management solutions
- Prior experience with federal compliance frameworks (NIST, FedRAMP, FISMA)
- Experience with multi‑cloud governance programs, Zero Trust architectures, and regulated enterprise environments
- Familiarity with DevSecOps practices, infrastructure‑as‑code security, and CI/CD pipeline hardening
- Security or SecOps certification from a major cloud service provider
- Strong collaboration and communication skills, with the ability to work effectively across cross‑functional teams
Nice to Have:
- Active Public Trust (High‑Risk) clearance
- Experience implementing Assured Workloads landing zones and structuring secure GCP resource hierarchies
- Experience securing container environments such as Google Kubernetes Engine (GKE)
- Proficiency configuring network security perimeters with GCP VPC Service Controls and OCI VCNs and Security Lists
- Experience with OCI Maximum Security Zones, Security Advisor, and Vulnerability Scanning Service
- Experience securing cloud databases and managing encryption keys with OCI Data Safe, OCI Vault, and Google/OCI KMS (including CMEK and HSMs)
- Threat hunting and vulnerability management experience using SIEM platforms and cloud‑native scanning services
Why Join Lumiture
- Be part of a growing startup where your work has an immediate impact
- Work directly with a team that values creativity, innovation, and exploration
- Access mentorship from experienced engineers and data scientists
- Enjoy flexibility, growth opportunities, and a culture built around learning fast and thinking bold
Let’s luminate the future - together!
Please follow our company page for ongoing updates!
https://www.linkedin.com/company/lumiture/